9.8

CVE-2005-3120

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

Data is provided by the National Vulnerability Database (NVD)
Invisible-islandLynx Version <= 2.8.6
DebianDebian Linux Version3.0
DebianDebian Linux Version3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 30.44% 0.963
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-131 Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

http://www.debian.org/security/2006/dsa-1085
Third Party Advisory
Mailing List
http://www.securityfocus.com/archive/1/435689/30/4740/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/15117
Third Party Advisory
Broken Link
VDB Entry
http://securitytracker.com/id?1015065
Third Party Advisory
Broken Link
VDB Entry
http://www.debian.org/security/2005/dsa-874
Third Party Advisory
Mailing List
http://www.debian.org/security/2005/dsa-876
Third Party Advisory
Mailing List
http://www.securityfocus.com/archive/1/419763/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry